Cryptographic trust for evidence — hash-chain proofs, signing, timestamping, and independent verification. Mock providers are labeled honestly.
Demo datasetStore: Demo Data
Illustrative pilot dataset — figures model a representative enterprise deployment.
@merritt/trust-engineComposite examination-readiness score
Append-only hash-chain verification
Mock signer — labeled, not legally binding until HSM/KMS is configured
Trust Level
signed mode
Verification
6 checks
Signature
not legally binding
Timestamp
PAdES-compatible signing abstraction. Mock until an HSM key is configured.
Signer types
Signing certificate lifecycle — subject, issuer, validity, and revocation.
Issuer: CN=CodexDominion Evidence Issuing CA · valid May 20, 2026 → Jun 25, 2027 · digitalSignature, nonRepudiation
Issuer: CN=CodexDominion Dev Root CA · valid Jun 25, 2025 → Jun 24, 2030 · keyCertSign, digitalSignature
Each audit event’s hash is re-derived and checked for continuity.
Events
8
Hashes re-derived
8
Failures
0
Confidence
high
Final chain digest (SHA-256)
0x35ddb268d7ff67558abb7306d10e1157bb8129a20414bebe383f979f790bc3eb
Method: SHA-256 re-derivation + prevHash continuity
Independently verify the trust manifest — hashes, digest, timestamp, signature, and certificate.
Warnings (honest mock disclosures)
Recommended remediation
Trust evidence documents — reuse the shared report shell.
CodexDominion Mock TSA
Hash Chain
8 hashes re-derived
RFC 3161-compatible interface. Mock TSA until a real authority is configured.
Issuer: CN=CodexDominion Dev Root CA · valid Jun 25, 2024 → Jun 23, 2034 · keyCertSign, cRLSign
Mock certificate chain — not anchored to a publicly trusted root. For development verification only.